
🤖 Another MCP project hit by command injection CVE-2026-19282 affects the llm_memory_mcp project. Manipulation of a hash argument in its Git hooks functionality can lead to command injection. The issue requires local execution and was published August 8. 🔎 Source: http://CVE.org / NVD / VulDB. #MCP #LLMSecurity #AISecurity #CVE #CyberSecurity
Post summary
The post announces CVE-2026-19282, a command injection flaw in llm_memory_mcp’s Git hooks that requires local execution, but does not provide a PoC, exploit code, patches, or evidence of active exploitation.


